You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
Moderate severity
GitHub Reviewed
Published
Sep 18, 2024
in
mautic/mautic
•
Updated Sep 27, 2024
With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session.
Impact
With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session.
Patches
Upgrade to 4.4.13 or 5.1.1 or later.
Workarounds
None
References
If you have any questions or comments about this advisory:
Email us at security@mautic.org
References